SCA: security update for @fastify/express (GHSA-g6q3-96cp-5r5m)

high Tenable Self-Hosted Container Security Plugin ID 436824

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in
@fastify/express prior to version 4.0.3 where middleware registered with a specific path prefix can be
bypassed using URL-encoded characters (e.g., `/%61dmin` instead of `/admin`). While the middleware engine
fails to match the encoded path and skips execution, the underlying Fastify router correctly decodes the
path and matches the route handler, allowing attackers to access protected endpoints without the
middleware constraints. The vulnerability is caused by how @fastify/express matches requests against
registered middleware paths. This vulnerability is similar to, but differs from, CVE-2026-22031 because
this is a different npm module with its own code. Version 4.0.3 of @fastify/express contains a patch fort
the issue. (CVE-2026-22037)

See Also

https://github.com/advisories/GHSA-g6q3-96cp-5r5m

Plugin Details

Severity: High

ID: 436824

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/20/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.39

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:P

CVSS Score Source: CVE-2026-22037

CVSS v3

Risk Factor: High

Base Score: 8.4

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/20/2026

Vulnerability Publication Date: 1/19/2026

Reference Information

CVE: CVE-2026-22037